Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 250444

Summary: [Tracker] >=sys-apps/dbus-1.2.12 security policy changes
Product: Gentoo Linux Reporter: Steev Klimaszewski (RETIRED) <steev>
Component: New packagesAssignee: Freedesktop bugs <freedesktop-bugs>
Severity: normal CC: aballier, coldwind, craig, jcallen, nirbheek
Priority: High Keywords: Tracker
Version: unspecified   
Hardware: All   
OS: Linux   
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 250546    
Attachments: dbus-1.2.10-fix-syslog-include.diff

Description Steev Klimaszewski (RETIRED) gentoo-dev 2008-12-09 21:45:04 UTC
Just opening this before any users do.  This one is going to need some changes to at least 8 other apps, and is a security release.  Going to be opening other bugs for those apps as I find them with the patches from upstream.

Upstream bugs: DBus Security issue Broken apps tracker
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-12-10 21:53:41 UTC
*** Bug 250546 has been marked as a duplicate of this bug. ***
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2009-01-04 14:20:28 UTC
Created attachment 177341 [details, diff]

Meanwhile dbus-1.2.10 was realeased. It doesn't compile out of the box as they forgot to include <syslog.h> in one file (see attched patch).
Comment 3 Steev Klimaszewski (RETIRED) gentoo-dev 2009-01-05 16:20:41 UTC
Yes, I know - again, anything equal to or greater than 1.2.8 breaks stuff, so it won't be going into the tree immediately - currently all my gentoo boxen (which are at home) are offline so I can't do anything to get this fixed yet.
Comment 4 Jonathan Callen (RETIRED) gentoo-dev 2009-04-01 02:54:35 UTC
If I'm not mistaken, there is a which is equivalent to 1.2.12, except that it doesn't break the things that >=1.2.8 breaks.
Comment 5 Gilles Dartiguelongue (RETIRED) gentoo-dev 2009-05-16 10:04:58 UTC
CCing  nirbheek so he can update us on status and attachements of this bug.
Comment 6 Gilles Dartiguelongue (RETIRED) gentoo-dev 2009-07-26 11:28:02 UTC
ok the syslog missing include is in 1.2.12, we need to review upstream tracker though to check every apps in tree has the fixes. Fixing summary for that purpose
Comment 7 Steev Klimaszewski (RETIRED) gentoo-dev 2011-07-31 20:14:50 UTC
Is this still needed?  Dbus 1.4.x is in the tree, and this bug is now almost 2 years old.
Comment 8 Gilles Dartiguelongue (RETIRED) gentoo-dev 2011-08-29 22:01:19 UTC
I guess that by now we would have heard of any broken app so I'm all for closing this bug.
Comment 9 Samuli Suominen (RETIRED) gentoo-dev 2011-09-08 16:29:31 UTC
I concur with last few comments and will close the bug now.